What is CVE-2026-66013?
A vulnerability in OpenRemote versions prior to 1.26.2 allows an authentication bypass in the console registration API. Unauthenticated attackers can exploit this by supplying a known asset identifier to overwrite push notification tokens and console metadata.
Azərbaycanca: OpenRemote platformunun 1.26.2-dən əvvəlki versiyalarında konsol qeydiyyat API-də autentifikasiyadan yan keçmə zəifliyi aşkarlanıb. Bu, autentifikasiya olunmamış hücumçulara məlum aktiv identifikatoru təqdim etməklə push notification token-lərini və konsol metadata-nı dəyişməyə imkan verir.
Related CVEs
link basis: same weakness class CWE-287
FAQ2
Does exploiting CVE-2026-66013 in the OpenRemote platform require authentication?
No, this vulnerability allows unauthenticated attackers to bypass authentication in the console registration API.
What data can an attacker modify through the CVE-2026-66013 vulnerability?
By supplying a known asset identifier, an attacker can overwrite push notification tokens and console metadata.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.